Incident Response
Zepp Health attaches great importance to security issues and welcomes all security researchers to report potential security vulnerabilities, helping us improve the security of our smartwatches and IoT devices (software, hardware, firmware).
Vulnerability Response and Disclosure Process
Our structured approach to handling reported vulnerabilities ensures timely and effective resolution.
Recipient
Monitor and assign received vulnerabilities in a timely manner
Verification
Verify the vulnerability and confirm the exploitability and impact
Solution Development
Provide effective fix solutions or risk remediation measures
Affected Scope Confirmation
Investigate and confirm the complete scope of affected products
Publish Advisory
Review and publish the security advisory for the security vulnerability
Reporting a Vulnerability
Submit your findings
Report discovered security vulnerabilities to our dedicated security team.
sec@zepp.comYour report should contain at least:
- Your organization and contact information
- Products and versions affected
- Description of the potential vulnerability
- Information about known exploits
- Disclosure plans
- Additional information
- Modification or destruction of data
- Service disruption or degradation (e.g. DoS)
- Disclosure of personal, proprietary or financial information
48-hour response
Zepp Health will respond within 48 hours to the vulnerabilities you submit.
Escalation and Decision Making
Escalation criteria are defined based on incident severity and impact to ensure critical vulnerabilities receive appropriate management attention without undue delay.
Escalation may be initiated when any of the following conditions are met:
- Confirmed active exploitation
- Significant impact to users or services
- Widespread product exposure
- Regulatory reporting obligations
- Inability to remediate within defined SLA timelines
Critical decisions — including public communication and regulatory reporting — are made by authorized roles based on predefined thresholds. Acknowledgement and communication activities may be prioritized or accelerated for vulnerabilities assessed as critical, actively exploited, or associated with significant customer or operational impact.